There is no security policy or automated security scanning, and one workflow reference is unpinned. The package includes a substantial README, repository tests, a license, and only one runtime dependency.
65%
Total Score
50
100
88
50
The package has only two releases, both published within about four minutes on the same day, leaving little evidence of a sustained release track. The repository was pushed recently, which partly offsets this concern.
There were no commits and no active maintainers in the last three months. The recent repository push is a compensating sign, but the lack of recent commit activity still limits confidence in ongoing maintenance.
Composer is used for builds, but no security-scanning tool is configured. This is a modest transparency and maintenance gap rather than evidence that the package is unsafe.
The repository has no security policy, so vulnerability reporting and response expectations are not documented.
The single workflow was fully analyzed with no audit findings or dangerous triggers. One of its two action references is unpinned, leaving a minor reproducibility and maintenance weakness.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.